blob: 04b925c08acdac3e0983588f4ab8cb5a066e3856 [file] [log] [blame]
Neale Rannsb1fd80f2020-05-12 13:33:56 +00001
2create packet-generator interface pg0
3create packet-generator interface pg1
4
5set int ip address pg0 192.168.0.1/24
6set int ip address pg1 192.168.1.1/24
7
8pipe create
9
10ip6 table add 1
11ip table add 1
12set int ip6 table pipe0.1 1
13set int ip table pipe0.1 1
14
15set int ip address pipe0.0 2001::1/64
16set int ip address pipe0.1 2001::2/64
17set int unnum pipe0.1 use pg1
18
19set int state pg0 up
20set int state pg1 up
21set int state pipe0 up
22
23ipsec sa add 20 spi 200 crypto-key 6541686776336961656264656f6f6579 crypto-alg aes-cbc-128 tunnel-src 2001::1 tunnel-dst 2001::2
24ipsec sa add 30 spi 200 crypto-key 6541686776336961656264656f6f6579 crypto-alg aes-cbc-128 tunnel-src 2001::1 tunnel-dst 2001::2
25
26ipsec spd add 1
27ipsec spd add 2
28set interface ipsec spd pipe0.0 1
29set interface ipsec spd pipe0.1 2
30ipsec policy add spd 1 ip6 priority 100 outbound action bypass protocol 50
31ipsec policy add spd 1 priority 10 outbound action protect sa 20 local-ip-range 192.168.0.0 - 192.168.0.255 remote-ip-range 10.6.0.0 - 10.6.255.255
32
33ipsec policy add spd 2 priority 10 inbound action protect sa 30 local-ip-range 2001::2 - 2001::2 remote-ip-range 2001::1 - 2001::1
34
35ip route add 10.6.0.0/16 via pipe0.0
36ip route table 1 add 10.6.0.0/16 via 192.168.1.2 pg1
37set ip neighbor pg1 192.168.1.2 00:11:22:33:44:55
38
39
40trace add pg-input 100
41
Damjan Marion3153f002022-05-14 00:14:02 +020042packet-generator new { \
43 name ipsec1 \
44 limit 1 \
45 rate 1e4 \
46 node ip4-input \
47 interface pg0 \
48 size 100-100 \
49 data { \
50 UDP: 192.168.0.2 -> 10.6.0.1 \
51 UDP: 4321 -> 1234 \
52 length 72 \
53 incrementing 100 \
54 } \
Neale Rannsb1fd80f2020-05-12 13:33:56 +000055}